Short answer: Do not open a downloaded DOC or PDF in Word, Acrobat, or another host app while that computer is online. Those programs fetch images, fonts, and links outside Tor and can show your real IP. The PDF viewer built into Tor Browser is the documented exception. Ignore the external-app warning and the path is gone.
This is a Tor Browser rule, not a general OPSEC essay. Identity and circuits are a different control: New Identity vs New Circuit.
What to do (in order)
- Save the file if you need it. Downloading is fine. Opening it in an external app while online is the leak.
- When Tor Browser asks before handing a file to an external application — cancel. The Project’s staying-anonymous page is blunt: do not ignore that warning.
- PDFs you only need to read — open them in Tor Browser’s built-in viewer (pdf.js). Fetches stay in the browser. That is the exception the same page names. It is not a license to click “Open with…” for convenience.
- Office files, or any file you must use in a host app — disconnect the machine from the network first, or move the file to a disconnected computer, or run it through Dangerzone to produce a safer PDF you can open. Dangerzone sanitizes documents; it does not make BitTorrent safe.
- Files you authored and will send — stripping GPS and author tags is a different job: photo and PDF metadata.
Only Tor Browser’s own traffic uses Tor. A reader on the same PC is another application.
What this is not
- It is not “downloads are forbidden.” Save the file. Open it later on a machine that is offline, or convert it first.
- It is not a substitute for Tails or a clean VM. Those shrink how much of the host can phone home.
- It is not the torrent problem. That is a hard no: why torrent and Tor don’t mix.
Sources
- Tor Project: Don’t open documents downloaded through Tor while online
- Freedom of the Press Foundation: Dangerzone
- Electronic Frontier Foundation: Surveillance Self-Defense
See also: photo and PDF metadata, why torrent and Tor don’t mix, OnionShare.